Somewhere in your house there's a blinking box, maybe two or three, and everyone calls one of them "the modem." Inside that plastic are five or six separate jobs: translating the line, routing, address translation, handing out addresses, answering name lookups, guarding the door, and running the Wi-Fi. Knowing which box does which job is the difference between guessing and fixing.
Common mix-up: the box your ISP gave you is rarely "just a modem." It's usually a gateway: modem, router, NAT, DHCP server, firewall, switch and Wi-Fi in one case. Plug your own router in behind it without changing anything, and you now have two routers each doing NAT, one behind the other. That's double NAT, and it's the most common home network problem nobody notices.
A home network is a small version of every network in this course. It has a link to the outside world, a border where your private addresses meet the public internet, a local segment where your devices talk to each other, and a radio that stretches that segment through the air. In an office each of those is a separate machine in a rack. At home they are usually squeezed into one or two boxes, which is why it's hard to tell them apart.
It helps to name the jobs before naming the boxes:
The layer model from Chapter 01 sorts them neatly. The modem works at layers 1 and 2: signals and frames. The switch and the access point work at layer 2: they read MAC addresses and nothing else. The router is the first box that reads IP addresses, layer 3, and because it does NAT it also reads and rewrites port numbers, which belong to layer 4. That one fact explains most of what follows: only the boxes that work at layer 3 change your packet's IP header. The others just carry it.
| Box | Layer | Reads | Changes in your packet |
|---|---|---|---|
| Modem / ONT | 1–2 | The line signal | Only the outer framing (Ethernet in, DOCSIS or GPON out) |
| Switch | 2 | Destination MAC | Nothing |
| Access point / mesh point | 2 | MAC addresses | Re-wraps an 802.11 radio frame as an Ethernet frame |
| Router | 3 (+4 for NAT) | Destination IP, ports | New MAC addresses, TTL − 1, and with NAT the source address and port |
| ISP gateway, router mode | 1–7 | Everything | All of the above, in one case |
| ISP gateway, bridge mode | 1–2 | The line signal | Behaves like a plain modem |
Your ISP's cable doesn't carry Ethernet. Cable internet runs over the same coax as cable TV, using a standard called DOCSIS that packs data into radio-frequency channels. DSL uses high-frequency tones on a telephone pair. Fiber uses light, and on most home fiber the box on your wall is an ONT, an optical network terminal, that speaks a passive optical network standard such as GPON, where one fiber from the street is split among a few dozen homes. Fixed wireless and 5G home internet use a radio on the roof or the windowsill.
Whatever the medium, the job is the same: a modem (modulator-demodulator, the old name from the dial-up days) turns the line's signal into Ethernet frames on one side and back again on the other. It is a translator between two physical worlds. It doesn't route, it doesn't hand out private addresses, it doesn't block anything. If you plug a single computer straight into a plain modem, that computer asks the ISP for an address by DHCP, gets the public address, and is directly on the internet with nothing in front of it.
That's why a modem is almost always followed by a router. The router plugs into the modem with its WAN port (wide area network, "the outside"), gets the public address from the ISP, and builds your private network on its LAN ports.
IPv4 addresses ran out years ago, and some ISPs (most mobile carriers, many 5G home and some fiber providers) no longer give each customer a public one. Instead your router's WAN port gets an address from 100.64.0.0/10, a block RFC 6598 set aside as "shared address space" for exactly this, and the ISP runs its own large NAT, carrier-grade NAT, in front of thousands of customers. Your traffic gets translated twice: once by your router, once by the carrier.
You can spot it in your router's status page: if the WAN address starts with 100. and the second number is between 64 and 127, you're behind CGNAT. (One catch: Tailscale also uses addresses from that same block for its own devices, so a 100.x address on a Tailscale adapter means something different.) Chapter 08 covers what CGNAT does to port forwarding.
A home router is the busiest box in the house. Strictly, "routing" is only the first of its jobs. The others ride along because the router is the one place every packet to and from the internet has to pass.
Most routers also contain a small switch, typically four LAN ports, and one or two Wi-Fi radios. So "the router" in everyday speech is really router, switch and access point together. The thing to keep straight is which of those jobs is happening where, because the router part is the only part that changes addresses.
RFC 1812, the requirements document for IPv4 routers, spells it out. A router receives a frame, checks that it's addressed to its own MAC address, unwraps the IP packet, and looks up the destination in its routing table. It lowers the TTL by one; if that makes it zero, it throws the packet away and sends an ICMP "time exceeded" message back to the sender. Then it recalculates the header checksum (it changed a field), finds the MAC address of the next hop with ARP, and wraps the packet in a fresh frame for the next link.
So even without NAT, the layer-2 envelope is brand new after every router, and one IP header field always changes. NAT adds two more: the source address and source port on the way out, and the destination address and port on the way back. Instrument 2 below shows each change happening, hop by hop.
On IPv6 the ISP usually hands your router a whole block of addresses by DHCPv6 prefix delegation (commonly a /56 or /64), and every device gets a real global address. RFC 7084 lists the basic requirements for these home routers, and RFC 6092 describes the default "outbound allowed, unsolicited inbound blocked" firewall they're expected to run instead of NAT.
Click any box to see what it does and which layer it works at. Use the presets or the switches to rearrange the house. The shaded bands are address spaces; every box marked NAT starts a new one. Watch the laptop's packet travel left: its source address changes each time it leaves through a NAT. Put the ISP gateway in bridge mode and one NAT disappears.
Addresses are typical defaults: 192.168.1.0/24 on the ISP gateway, 192.168.86.0/24 on the mesh router, a documentation address standing in for the public one.
Inside your network, devices talk to each other with Ethernet frames addressed by MAC address, as Chapter 02 explains. A switch learns which MAC address lives behind which port by watching the source address of every frame that arrives, and from then on sends each frame only out the right port. It never looks at IP addresses. A cheap unmanaged five-port switch behind your TV is just a way to turn one wall jack into four, and every device plugged into it is on exactly the same network as everything else.
An access point does the same thing with radio. Your laptop sends an 802.11 frame through the air; the access point receives it and re-sends the same data as an Ethernet frame on its wired side, and the reverse for traffic coming back. That makes it a bridge between two kinds of layer 2. Your laptop's IP address, the router's address, the TTL: none of it changes. A device on Wi-Fi and a device on a cable, both behind the same router, are neighbors on one subnet.
A mesh system is several access points that coordinate. One unit, the main one, usually also acts as the router. The others, satellites or "points," connect back to it either by cable or by Wi-Fi itself (the backhaul), and they all broadcast the same network name, so your phone can roam from one to the next. Mesh points are bridges too: adding a third or fourth one never adds another NAT, only more coverage.
The trouble starts when a box that could be a router is installed where only a bridge was needed. Most mesh kits and retail routers come out of the box in router mode, with NAT and a DHCP server switched on. Put one behind an ISP gateway that's also in router mode and you get two routers in a row. Most of these products offer a "bridge mode" or "access point mode" that turns their router functions off, and that, or turning the ISP gateway's off instead, is usually the fix.
An Ethernet frame has two addresses, source and destination. An 802.11 data frame in a normal home network carries three: the radio that sent it, the radio that should receive it, and the final destination or original source on the wired side. When your laptop sends to the router through an access point, the frame says "from laptop, to access point (the BSSID), final destination router." The access point copies the laptop and router addresses into an ordinary Ethernet frame. The fourth address field exists for wireless-to-wireless bridging, which is what some mesh backhaul links use.
Wireless backhaul has a cost. A mesh point with one radio has to receive your data over the air and then send it again over the air to the main unit, on the same channel, so the airtime is used twice. Tri-band mesh systems put the backhaul on a separate radio to avoid that. A cable between mesh points, if your house has one, beats both.
Wi-Fi is radio, and the physics deserves a whole chapter. The companion site already has one: waves.jelia.nyc/2-4-ghz walks through what a 2.4 GHz wave is, why water and walls absorb it, and how antennas send it. Here is the network engineer's short version.
Three bands. Home Wi-Fi uses the 2.4 GHz band, the 5 GHz band and, with Wi-Fi 6E and Wi-Fi 7 equipment, the 6 GHz band. Each band is divided into channels. Two networks on the same channel take turns using the air; two on overlapping channels interfere with each other in a messier way.
2.4 GHz is crowded. Its channels are only 5 MHz apart, but a Wi-Fi signal is about 20 MHz wide, so neighboring channel numbers overlap. In North America that leaves 1, 6 and 11 as the only three that don't. Microwave ovens, Bluetooth and every neighbor's router share the same small slice. In exchange, 2.4 GHz reaches farther and gets through walls better.
5 GHz and 6 GHz are roomy. Far more channels, and they can be bonded into wider ones (40, 80, 160 MHz, and 320 MHz in Wi-Fi 7 at 6 GHz) for more speed. The price is range. Higher frequencies generally lose more of their strength going through walls, floors and furniture, so a 5 GHz signal that's excellent in the same room may be weak two rooms away. Some 5 GHz channels, the DFS channels, are shared with weather and military radar, and a router using them must listen for radar and move off if it hears any.
Why walls matter. Signal strength falls off with distance even in open air, and every wall takes another bite. Drywall takes a little, brick and concrete a lot, metal, mirrors and foil-backed insulation nearly everything. A water heater or a fish tank in the way is a surprisingly good shield. That's the whole case for mesh: rather than one loud radio shouting through four walls, put a quieter one in each part of the house.
| Band | Channel widths | Strength | Weakness |
|---|---|---|---|
| 2.4 GHz | 20 MHz (40 rarely useful) | Range, gets through walls, every device supports it | Only 3 non-overlapping channels; crowded; slowest |
| 5 GHz | 20 / 40 / 80 / 160 MHz | Many channels, much faster | Shorter reach; DFS channels may switch when radar is detected |
| 6 GHz | up to 160 MHz; 320 MHz with Wi-Fi 7 | Wide, clean channels; only newer devices, so little congestion | Shortest reach of the three; needs Wi-Fi 6E or 7 devices |
The number on the box is the PHY rate: the fastest a single device could signal under perfect conditions, at the widest channel, with every antenna stream in use. Real throughput is often half that or less. Part of the gap is overhead: every frame waits a random backoff before sending (Wi-Fi's medium access method is CSMA/CA, carrier sense with collision avoidance), and every unicast frame gets an acknowledgment. Part is distance, since the radio drops to slower, more robust encodings as the signal weakens. And part is sharing: all devices on a channel take turns, including your neighbors'.
Wi-Fi on a given channel is half-duplex: one radio talks at a time. Switched Ethernet is full-duplex: each cable carries traffic in both directions at once, and a switch gives each port its own collision-free link. That's the root of the wired-versus-wireless difference below.
Both are layer 2; both carry exactly the same IP packets. The difference is in how predictable the trip is.
The rule of thumb: anything that doesn't move and is near a jack should be wired, especially a desktop, a game console, a TV, a NAS, and above all the link between mesh points. Wi-Fi is for things that move. If you can't run cable, powerline and MoCA (Ethernet over the coax already in your walls) adapters are worth a look; they are bridges too, so they add no NAT.
Three commands tell you most of what you need: your address, your default gateway, and the first few routers out of the house.
Your address and gateway. On Windows, open a terminal and run ipconfig. Find the adapter you're actually using (Wi-Fi or Ethernet; ignore the virtual ones for now, Chapter 12 deals with them) and read three lines:
Wireless LAN adapter Wi-Fi: IPv4 Address. . . . . . . . . . . : 192.168.86.57 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.86.1
On Linux, ip addr shows addresses and ip route shows the gateway in a line like default via 192.168.86.1 dev wlan0. On macOS, ipconfig getifaddr en0 prints the Wi-Fi address and route -n get default prints the gateway. The default gateway is your router's LAN address: the first box that will change your packets.
The first hops out. Now ask every router on the way out to identify itself. On Windows, tracert -d -h 5 example.com (-d skips name lookups so it's faster, -h 5 stops after five hops); on macOS or Linux, traceroute -n -m 5 example.com. Each line is one router, found by sending packets with TTL 1, then 2, then 3, and listening for the "time exceeded" messages that come back.
Tracing route to example.com [198.51.100.80] over a maximum of 5 hops: 1 3 ms 2 ms 3 ms 192.168.86.1 2 4 ms 4 ms 5 ms 192.168.1.1 3 12 ms 11 ms 13 ms 203.0.113.1 4 14 ms 13 ms 15 ms 198.51.100.9 5 15 ms 14 ms 14 ms 198.51.100.80
Read the addresses, not the times. Hop 1 is your own router. Then count how many hops in a row have private addresses: 10.x.x.x, 172.16–31.x.x or 192.168.x.x. One private hop is normal. Two private hops, as above, mean a router behind a router: double NAT. A hop in 100.64–127.x.x right after them points to carrier-grade NAT. The first public address is the ISP's side of the border. Notice what never shows up: the switch, the access point and the mesh points. They don't touch TTL, so traceroute can't see them.
ipconfig /all on Windows adds each adapter's MAC address, its DHCP server and lease times, and its DNS servers. If the DHCP server and the default gateway are the same address, that's your router. route print shows the full routing table, and PowerShell's Get-NetIPConfiguration gives a tidy per-adapter summary.
Then open the router's admin page: type the default gateway address into a browser. Its status page shows the WAN address it received. If that WAN address is itself private (say 192.168.1.20), this router sits behind another one, and you've found double NAT from the other end. If it's in 100.64.0.0/10, the "other router" is your ISP's.
Windows tracert sends ICMP echo requests; the Unix traceroute sends UDP packets to high port numbers by default. Some routers ignore one kind or rate-limit their replies, which shows as * for a hop. A star is not necessarily a failure. Chapter 13 covers reading traceroutes properly.
Follow one packet from a laptop to a website, a hop at a time. The card shows the frame's outer envelope (layer 2) and the packet inside (layers 3 and 4); anything that changed at this hop is highlighted, with its old value underneath. Each NAT keeps a real translation table, so open a second connection, or have the phone use the same port, and watch the router pick a different one. Then send the reply back, or try an unsolicited packet from outside.
MAC addresses are invented, locally administered ones. The internet core is shown as one stop that lowers TTL by five, standing in for five routers.
Double NAT is easy to create and easy to miss, because ordinary browsing works fine through it. Every outbound connection gets translated twice and the replies find their way back through both tables. The problems only show up when something needs to come in, or when two devices want to find each other directly.
The symptoms, in roughly the order people notice them:
That last one is the case that started this site. A Windows laptop on a mesh network at 192.168.86.x, behind an ISP gateway at 192.168.1.x, kept retrying NAT-PMP port-mapping requests, and its Remote Desktop sessions over Tailscale ran through a DERP relay instead of the direct path. Every screen update made a round trip through a distant server. The fixes are the same as for any double NAT: put one of the two boxes in bridge or access-point mode so only one does NAT, or, if the ISP box can't be bridged, use its "IP passthrough" or DMZ setting to hand everything to your router. Chapter 08 takes it apart properly, and Chapter 09 explains the direct-versus-relay decision.
Bridge mode on an ISP gateway turns off its router, NAT, DHCP server and usually its Wi-Fi, and passes the public address through to whatever is plugged into it. The gateway becomes a modem. Your router then gets the public address and is the only NAT.
Access point mode (some brands say "bridge mode" here too, confusingly) is the same idea from the other side: your own router or mesh stops routing and simply extends the ISP gateway's network over Wi-Fi. Only one NAT remains, but the ISP box is in charge of DHCP and the firewall, and some mesh features need router mode to work.
IP passthrough (the name varies by ISP) keeps the gateway's router running but gives your router the public address anyway. DMZ host is weaker: the gateway still does NAT but forwards every unsolicited inbound port to one inside address, your router. It fixes inbound forwarding but leaves the double translation in place.